|
---825423385-869861078-1060018423=:14851 Content-Type: TEXT/PLAIN; charset=US-ASCII Originally reported as affecting only WU-FTPD. It seems that the bug is in code borrowed from the BSD C library. NetBSD, FreeBSD and OpenBSD announcements attached. David Mirza Ahmad Symantec PGP: 0x26005712 8D 9A B1 33 82 3D B3 D0 40 EB AB F0 1E 67 C6 1A 26 00 57 12 -- The battle for the past is for the future. We must be the winners of the memory war. ---825423385-869861078-1060018423=:14851 Content-Type: MESSAGE/RFC822; CHARSET=US-ASCII Content-ID: <Pine.LNX.4.55.0308041127340.14851@mail.securityfocus.com> Content-Description: off-by-one error in realpath(3) (fwd) Return-Path: <owner-security-announce+M37@openbsd.org> Delivered-To: da@securityfocus.com Received: (qmail 20390 invoked by alias); 4 Aug 2003 17:23:27 -0000 Received: from openbsd.cs.colorado.edu (128.138.192.83) by mail.securityfocus.com with SMTP; 4 Aug 2003 17:23:27 -0000 Received: from openbsd.org (localhost.cs.colorado.edu [127.0.0.1]) by openbsd.cs.colorado.edu (8.12.9/8.12.9) with ESMTP id h74HQ9A4002552; Mon, 4 Aug 2003 11:26:47 -0600 (MDT) Received: from xerxes.courtesan.com (courtesan.com [206.168.103.86]) by openbsd.cs.colorado.edu (8.12.9/8.12.9) with ESMTP id h74H36Pq006015 (version=TLSv1/SSLv3 cipher=DHE-DSS-AES256-SHA bits=256 verify=FAIL) for <security-announce@openbsd.org>; Mon, 4 Aug 2003 11:03:11 -0600 (MDT) Received: from xerxes.courtesan.com (IDENT:millert@localhost.courtesan.com [127.0.0.1]) by xerxes.courtesan.com (8.12.10.Beta2/8.12.10.Beta2) with ESMTP id h74H36co022239 for <security-announce@openbsd.org>; Mon, 4 Aug 2003 11:03:06 -0600 (MDT) Message-Id: <200308041703.h74H36co022239@xerxes.courtesan.com> To: security-announce@openbsd.org Subject: off-by-one error in realpath(3) Date: Mon, 04 Aug 2003 11:03:06 -0600 From: "Todd C. Miller" <Todd.Miller@courtesan.com> X-Spam-Level: X-Spam-Checker-Version: SpamAssassin 2.55 (1.174.2.19-2003-05-19-exp) X-Loop: security-announce@openbsd.org Precedence: list Sender: owner-security-announce@openbsd.org MIME-Version: 1.0 [ this version has some typos fixed ] An off-by-one error exists in the C library function realpath(3). This is the same bug that was recently found in the wu-ftpd ftpd server by Janusz Niewiadomski and Janusz Niewiadomski. The OpenBSD ftp daemon does not use realpath(3) in a way that could be exploited, however a number of other system binaries also use the function. It is not currently known whether or not this bug results in an exploitable security hole on OpenBSD. Since the bug led to an exploitable hole in wu-ftpd, it is entirely possible that some program using realpath(3) under OpenBSD may be vulnerable to attack. For OpenBSD 3.3 and higher, the ProPolice stack protector should provide some protection from this bug, but this cannot be guaranteed. This bug has been fixed in OpenBSD-current as well as the 3.2 and 3.3 stable branches. Patches are available for OpenBSD 3.2 and 3.3. Patch for OpenBSD 3.2: ftp://ftp.OpenBSD.org/pub/OpenBSD/patches/3.2/common/015_realpath.patch Patch for OpenBSD 3.3: ftp://ftp.OpenBSD.org/pub/OpenBSD/patches/3.3/common/001_realpath.patch For versions of OpenBSD prior to 3.2, users may simply fetch the current revision of realpath.c from: ftp://ftp.OpenBSD.org/pub/OpenBSD/src/lib/libc/stdlib/realpath.c then rebuild and install libc with the new realpath.c. For more details, see the description of the wu-ftpd fp_realpath bug: http://isec.pl/vulnerabilities/isec-0011-wu-ftpd.txt ---825423385-869861078-1060018423=:14851 Content-Type: TEXT/PLAIN; charset=US-ASCII; name="FreeBSD-SA-03:08.realpath" Content-Transfer-Encoding: BASE64 Content-ID: <Pine.LNX.4.55.0308041133430.14851@mail.securityfocus.com> Content-Description: Content-Disposition: attachment; filename="FreeBSD-SA-03:08.realpath" RnJvbSBzZWN1cml0eS1hZHZpc29yaWVzQGZyZWVic2Qub3JnIE1vbiBBdWcg IDQgMTE6MjY6MDMgMjAwMw0KUmV0dXJuLVBhdGg6IDxvd25lci1mcmVlYnNk LXNlY3VyaXR5QGZyZWVic2Qub3JnPg0KRGVsaXZlcmVkLVRvOiBkYUBzZWN1 cml0eWZvY3VzLmNvbQ0KUmVjZWl2ZWQ6IChxbWFpbCAxNjAxOSBpbnZva2Vk IGZyb20gbmV0d29yayk7IDQgQXVnIDIwMDMgMDA6MDE6MzggLTAwMDANClJl Y2VpdmVkOiBmcm9tIG14Mi5mcmVlYnNkLm9yZyAoMjE2LjEzNi4yMDQuMTE5 KQ0KICBieSBtYWlsLnNlY3VyaXR5Zm9jdXMuY29tIHdpdGggU01UUDsgNCBB dWcgMjAwMyAwMDowMTozOCAtMDAwMA0KUmVjZWl2ZWQ6IGZyb20gaHViLmZy ZWVic2Qub3JnIChodWIuZnJlZWJzZC5vcmcgWzIxNi4xMzYuMjA0LjE4XSkN CglieSBteDIuZnJlZWJzZC5vcmcgKFBvc3RmaXgpIHdpdGggRVNNVFANCglp ZCAzMTg5MDU2QkMzOyBTdW4sICAzIEF1ZyAyMDAzIDE3OjA0OjUwIC0wNzAw IChQRFQpDQoJKGVudmVsb3BlLWZyb20gb3duZXItZnJlZWJzZC1zZWN1cml0 eUBmcmVlYnNkLm9yZykNClJlY2VpdmVkOiBmcm9tIGh1Yi5mcmVlYnNkLm9y ZyAobG9jYWxob3N0IFsxMjcuMC4wLjFdKQ0KCWJ5IGh1Yi5mcmVlYnNkLm9y ZyAoUG9zdGZpeCkgd2l0aCBFU01UUA0KCWlkIEJCQ0I0MzdCNDA5OyBTdW4s ICAzIEF1ZyAyMDAzIDE3OjA0OjQ4IC0wNzAwIChQRFQpDQpEZWxpdmVyZWQt VG86IGZyZWVic2Qtc2VjdXJpdHlAZnJlZWJzZC5vcmcNClJlY2VpdmVkOiBm cm9tIG14MS5GcmVlQlNELm9yZyAobXgxLmZyZWVic2Qub3JnIFsyMTYuMTM2 LjIwNC4xMjVdKQ0KCWJ5IGh1Yi5mcmVlYnNkLm9yZyAoUG9zdGZpeCkgd2l0 aCBFU01UUA0KCWlkIDM5MUFDMzdCNDA0OyBTdW4sICAzIEF1ZyAyMDAzIDE3 OjA0OjMzIC0wNzAwIChQRFQpDQpSZWNlaXZlZDogZnJvbSBmcmVlZmFsbC5m cmVlYnNkLm9yZyAoZnJlZWZhbGwuZnJlZWJzZC5vcmcgWzIxNi4xMzYuMjA0 LjIxXSkNCglieSBteDEuRnJlZUJTRC5vcmcgKFBvc3RmaXgpIHdpdGggRVNN VFANCglpZCA0RkNDRjQzRkFGOyBTdW4sICAzIEF1ZyAyMDAzIDE3OjA0OjMx IC0wNzAwIChQRFQpDQoJKGVudmVsb3BlLWZyb20gc2VjdXJpdHktYWR2aXNv cmllc0BmcmVlYnNkLm9yZykNClJlY2VpdmVkOiBmcm9tIGZyZWVmYWxsLmZy ZWVic2Qub3JnIChuZWN0YXJAbG9jYWxob3N0IFsxMjcuMC4wLjFdKQ0KCWJ5 IGZyZWVmYWxsLmZyZWVic2Qub3JnICg4LjEyLjkvOC4xMi45KSB3aXRoIEVT TVRQIGlkDQogICAgaDc0MDRWVXAwMzA2NzM7DQoJU3VuLCAzIEF1ZyAyMDAz IDE3OjA0OjMxIC0wNzAwIChQRFQpDQoJKGVudmVsb3BlLWZyb20gc2VjdXJp dHktYWR2aXNvcmllc0BmcmVlYnNkLm9yZykNClJlY2VpdmVkOiAoZnJvbSBu ZWN0YXJAbG9jYWxob3N0KQ0KCWJ5IGZyZWVmYWxsLmZyZWVic2Qub3JnICg4 LjEyLjkvOC4xMi45L1N1Ym1pdCkgaWQgaDc0MDRWVkwwMzA2NzE7DQoJU3Vu LCAzIEF1ZyAyMDAzIDE3OjA0OjMxIC0wNzAwIChQRFQpDQpEYXRlOiBTdW4s IDMgQXVnIDIwMDMgMTc6MDQ6MzEgLTA3MDAgKFBEVCkNCk1lc3NhZ2UtSWQ6 IDwyMDAzMDgwNDAwMDQuaDc0MDRWVkwwMzA2NzFAZnJlZWZhbGwuZnJlZWJz ZC5vcmc+DQpYLUF1dGhlbnRpY2F0aW9uLVdhcm5pbmc6IGZyZWVmYWxsLmZy ZWVic2Qub3JnOiBuZWN0YXIgc2V0IHNlbmRlciB0bw0KCXNlY3VyaXR5LWFk dmlzb3JpZXNAZnJlZWJzZC5vcmcgdXNpbmcgLWYNCkZyb206IEZyZWVCU0Qg U2VjdXJpdHkgQWR2aXNvcmllcyA8c2VjdXJpdHktYWR2aXNvcmllc0BmcmVl YnNkLm9yZz4NClRvOiBGcmVlQlNEIFNlY3VyaXR5IEFkdmlzb3JpZXMgPHNl Y3VyaXR5LWFkdmlzb3JpZXNAZnJlZWJzZC5vcmc+DQpQcmVjZWRlbmNlOiBi dWxrDQpTdWJqZWN0OiBGcmVlQlNEIFNlY3VyaXR5IEFkdmlzb3J5IEZyZWVC U0QtU0EtMDM6MDgucmVhbHBhdGgNClgtQmVlblRoZXJlOiBmcmVlYnNkLXNl Y3VyaXR5QGZyZWVic2Qub3JnDQpYLU1haWxtYW4tVmVyc2lvbjogMi4xLjEN ClJlcGx5LVRvOiBzZWN1cml0eS1hZHZpc29yaWVzQGZyZWVic2Qub3JnDQpM aXN0LUlkOiBTZWN1cml0eSBpc3N1ZXMgW21lbWJlcnMtb25seSBwb3N0aW5n XQ0KCTxmcmVlYnNkLXNlY3VyaXR5LmZyZWVic2Qub3JnPg0KTGlzdC1VbnN1 YnNjcmliZToNCiAgICA8aHR0cDovL2xpc3RzLmZyZWVic2Qub3JnL21haWxt YW4vbGlzdGluZm8vZnJlZWJzZC1zZWN1cml0eT4sDQoJPG1haWx0bzpmcmVl YnNkLXNlY3VyaXR5LXJlcXVlc3RAZnJlZWJzZC5vcmc/c3ViamVjdD11bnN1 YnNjcmliZT4NCkxpc3QtQXJjaGl2ZTogPGh0dHA6Ly9saXN0cy5mcmVlYnNk Lm9yZy9waXBlcm1haWwvZnJlZWJzZC1zZWN1cml0eT4NCkxpc3QtUG9zdDog PG1haWx0bzpmcmVlYnNkLXNlY3VyaXR5QGZyZWVic2Qub3JnPg0KTGlzdC1I ZWxwOiA8bWFpbHRvOmZyZWVic2Qtc2VjdXJpdHktcmVxdWVzdEBmcmVlYnNk Lm9yZz9zdWJqZWN0PWhlbHA+DQpMaXN0LVN1YnNjcmliZTogPGh0dHA6Ly9s aXN0cy5mcmVlYnNkLm9yZy9tYWlsbWFuL2xpc3RpbmZvL2ZyZWVic2Qtc2Vj dXJpdHk+LA0KCTxtYWlsdG86ZnJlZWJzZC1zZWN1cml0eS1yZXF1ZXN0QGZy ZWVic2Qub3JnP3N1YmplY3Q9c3Vic2NyaWJlPg0KU2VuZGVyOiBvd25lci1m cmVlYnNkLXNlY3VyaXR5QGZyZWVic2Qub3JnDQpFcnJvcnMtVG86IG93bmVy LWZyZWVic2Qtc2VjdXJpdHlAZnJlZWJzZC5vcmcNCg0KLS0tLS1CRUdJTiBQ R1AgU0lHTkVEIE1FU1NBR0UtLS0tLQ0KSGFzaDogU0hBMQ0KDQo9PT09PT09 PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09 PT09PT09PT09PT09PT09PT09PT09PT09PQ0KRnJlZUJTRC1TQS0wMzowOC5y ZWFscGF0aCAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgU2Vj dXJpdHkgQWR2aXNvcnkNCiAgICAgICAgICAgICAgICAgICAgICAgICAgICAg ICAgICAgICAgICAgICAgICAgICAgICAgICAgICBUaGUgRnJlZUJTRCBQcm9q ZWN0DQoNClRvcGljOiAgICAgICAgICBTaW5nbGUgYnl0ZSBidWZmZXIgb3Zl cmZsb3cgaW4gcmVhbHBhdGgoMykNCg0KQ2F0ZWdvcnk6ICAgICAgIGNvcmUN Ck1vZHVsZTogICAgICAgICBsaWJjDQpBbm5vdW5jZWQ6ICAgICAgMjAwMy0w OC0wMw0KQ3JlZGl0czogICAgICAgIEphbnVzeiBOaWV3aWFkb21za2kgPGZ1 bmt5c2hAaXNlYy5wbD4sDQogICAgICAgICAgICAgICAgV29qY2llY2ggUHVy Y3p5bnNraSA8Y2xpcGhAaXNlYy5wbD4sDQogICAgICAgICAgICAgICAgQ0VS VC9DQw0KQWZmZWN0czogICAgICAgIEFsbCByZWxlYXNlcyBvZiBGcmVlQlNE IHVwIHRvIGFuZCBpbmNsdWRpbmcgNC44LVJFTEVBU0UNCiAgICAgICAgICAg ICAgICBhbmQgNS4wLVJFTEVBU0UNCiAgICAgICAgICAgICAgICBGcmVlQlNE IDQtU1RBQkxFIHByaW9yIHRvIE1heSAyMiAxNzoxMTo0NCAyMDAzIFVUQw0K Q29ycmVjdGVkOiAgICAgIDIwMDMtMDgtMDMgMjM6NDY6MjQgVVRDIChSRUxF TkdfNV8wKQ0KICAgICAgICAgICAgICAgIDIwMDMtMDgtMDMgMjM6NDM6NDMg VVRDIChSRUxFTkdfNF84KQ0KICAgICAgICAgICAgICAgIDIwMDMtMDgtMDMg MjM6NDQ6MTIgVVRDIChSRUxFTkdfNF83KQ0KICAgICAgICAgICAgICAgIDIw MDMtMDgtMDMgMjM6NDQ6MzYgVVRDIChSRUxFTkdfNF82KQ0KICAgICAgICAg ICAgICAgIDIwMDMtMDgtMDMgMjM6NDQ6NTYgVVRDIChSRUxFTkdfNF81KQ0K ICAgICAgICAgICAgICAgIDIwMDMtMDgtMDMgMjM6NDU6NDEgVVRDIChSRUxF TkdfNF80KQ0KICAgICAgICAgICAgICAgIDIwMDMtMDgtMDMgMjM6NDY6MDMg VVRDIChSRUxFTkdfNF8zKQ0KICAgICAgICAgICAgICAgIDIwMDMtMDgtMDMg MjM6NDc6MzkgVVRDIChSRUxFTkdfMykNCkZyZWVCU0Qgb25seTogICBOTw0K DQpJLiAgIEJhY2tncm91bmQNCg0KVGhlIHJlYWxwYXRoKDMpIGZ1bmN0aW9u IGlzIHVzZWQgdG8gZGV0ZXJtaW5lIHRoZSBjYW5vbmljYWwsDQphYnNvbHV0 ZSBwYXRobmFtZSBmcm9tIGEgZ2l2ZW4gcGF0aG5hbWUgd2hpY2ggbWF5IGNv bnRhaW4gZXh0cmENCmBgLycnIGNoYXJhY3RlcnMsIHJlZmVyZW5jZXMgdG8g YGAvLi8nJyBvciBgYC8uLi8nJywgb3IgcmVmZXJlbmNlcw0KdG8gc3ltYm9s aWMgbGlua3MuICBUaGUgcmVhbHBhdGgoMykgZnVuY3Rpb24gaXMgcGFydCBv ZiB0aGUgRnJlZUJTRA0KU3RhbmRhcmQgQyBMaWJyYXJ5Lg0KDQpJSS4gIFBy b2JsZW0gRGVzY3JpcHRpb24NCg0KQW4gb2ZmLWJ5LW9uZSBlcnJvciBleGlz dHMgaW4gYSBwb3J0aW9uIG9mIHJlYWxwYXRoKDMpIHRoYXQgY29tcHV0ZXMN CnRoZSBsZW5ndGggb2YgdGhlIHJlc29sdmVkIHBhdGhuYW1lLiAgQXMgYSBy ZXN1bHQsIGlmIHRoZSByZXNvbHZlZA0KcGF0aCBuYW1lIGlzIGV4YWN0bHkg MTAyNCBjaGFyYWN0ZXJzIGxvbmcgYW5kIGNvbnRhaW5zIGF0IGxlYXN0DQp0 d28gZGlyZWN0b3J5IHNlcGFyYXRvcnMsIHRoZSBidWZmZXIgcGFzc2VkIHRv IHJlYWxwYXRoKDMpIHdpbGwgYmUNCm92ZXJ3cml0dGVuIGJ5IGEgc2luZ2xl IE5VTCBieXRlLg0KDQpJSUkuIEltcGFjdA0KDQpBcHBsaWNhdGlvbnMgdXNp bmcgcmVhbHBhdGgoMykgTUFZIGJlIHZ1bG5lcmFibGUgdG8gZGVuaWFsIG9m IHNlcnZpY2UNCmF0dGFja3MsIHJlbW90ZSBjb2RlIGV4ZWN1dGlvbiwgYW5k L29yIHByaXZpbGVnZSBlc2NhbGF0aW9uLiAgVGhlDQppbXBhY3Qgb24gYW4g aW5kaXZpZHVhbCBhcHBsaWNhdGlvbiBpcyBoaWdobHkgZGVwZW5kZW50IHVw b24gdGhlDQpzb3VyY2Ugb2YgdGhlIHBhdGhuYW1lIHBhc3NlZCB0byByZWFs cGF0aCwgdGhlIHBvc2l0aW9uIG9mIHRoZSBvdXRwdXQNCmJ1ZmZlciBvbiB0 aGUgc3RhY2ssIHRoZSBhcmNoaXRlY3R1cmUgb24gd2hpY2ggdGhlIGFwcGxp Y2F0aW9uIGlzDQpydW5uaW5nLCBhbmQgb3RoZXIgZmFjdG9ycy4NCg0KV2l0 aGluIHRoZSBGcmVlQlNEIGJhc2Ugc3lzdGVtLCBzZXZlcmFsIGFwcGxpY2F0 aW9ucyB1c2UgcmVhbHBhdGgoMykuDQpUd28gYXBwbGljYXRpb25zIHdoaWNo IGFyZSBuZWdhdGl2ZWx5IGltcGFjdGVkIGFyZToNCg0KKDEpIGx1a2VtZnRw ZCg4KSwgYW4gYWx0ZXJuYXRpdmUgRlRQIHNlcnZlcjogcmVhbHBhdGgoMykg aXMgdXNlZCB0bw0KICAgIHByb2Nlc3MgdGhlIE1MU1QgYW5kIE1MU0QgY29t bWFuZHMuICBbbHVrZW1mdHBkKDgpIGlzIG5vdCBidWlsdCBvcg0KICAgIGlu c3RhbGxlZCBieSBkZWZhdWx0Ll0NCg0KKDIpIHNmdHAtc2VydmVyKDgpLCBw YXJ0IG9mIE9wZW5TU0g6IHJlYWxwYXRoKDMpIGlzIHVzZWQgdG8gcHJvY2Vz cw0KICAgIGNoZGlyIGNvbW1hbmRzLg0KDQpJbiBib3RoIG9mIHRoZSBjYXNl cyBhYm92ZSwgdGhlIHJlYWxwYXRoKDMpIHZ1bG5lcmFiaWxpdHkgbWF5IGJl DQpleHBsb2l0YWJsZSwgbGVhZGluZyB0byBhcmJpdHJhcnkgY29kZSBleGVj dXRpb24gd2l0aCB0aGUgcHJpdmlsZWdlcw0Kb2YgdGhlIGF1dGhlbnRpY2F0 ZWQgdXNlci4gIFRoaXMgaXMgcHJvYmFibHkgb25seSBvZiBjb25jZXJuIG9u DQpvdGhlcndpc2UgYGNsb3NlZCcgc2VydmVycywgZS5nLiBzZXJ2ZXJzIHdp dGhvdXQgc2hlbGwgYWNjZXNzLg0KDQpBdCB0aGUgdGltZSBvZiA0LjgtUkVM RUFTRSwgdGhlIEZyZWVCU0QgUG9ydHMgQ29sbGVjdGlvbiBjb250YWluZWQN CnRoZSBmb2xsb3dpbmcgYXBwbGljYXRpb25zIHdoaWNoIGFwcGVhciB0byB1 c2UgcmVhbHBhdGgoMykuICBUaGVzZQ0KYXBwbGljYXRpb25zIGhhdmUgbm90 IGJlZW4gYXVkaXRlZCwgYW5kIG1heSBvciBtYXkgbm90IGJlIHZ1bG5lcmFi bGUuDQpUaGVyZSBtYXkgYmUgYWRkaXRpb25hbCBhcHBsaWNhdGlvbnMgaW4g dGhlIEZyZWVCU0QgUG9ydHMgQ29sbGVjdGlvbg0KdGhhdCB1c2UgcmVhbHBh dGgoMyksIHBhcnRpY3VsYXJseSBzdGF0aWNhbGx5LWxpbmtlZCBhcHBsaWNh dGlvbnMgYW5kDQphcHBsaWNhdGlvbnMgYWRkZWQgc2luY2UgNC44LVJFTEVB U0UuDQoNCkJpdGNoWC0xLjBjMTlfMQ0KTW93aXR6LTAuMi4xXzENClhGcmVl ODYtY2xpZW50cy00LjMuMF8xDQphYmNhY2hlLTAuMTQNCmFpbS0xLjUuMjM0 DQphbmFsb2ctNS4yNCwxDQphbmp1dGEtMS4wLjFfMQ0KYW9sc2VydmVyLTMu NC4yDQphcmd1cy0yLjAuNQ0KYXJtLXJ0ZW1zLWdkYi01LjJfMQ0KYXZyLWdk Yi01LjIuMQ0KY2NhY2hlLTIuMS4xDQpjZHBhcmFub2lhLTMuOS44XzQNCmNm ZW5naW5lLTEuNi4zXzQNCmNmZW5naW5lMi0yLjAuMw0KY21ha2UtMS40LjcN CmNvbXNlcnYtMS40LjMNCmNyaXRpY2FsbWFzcy0wLjk3DQpkZWRpdC0wLjYu Mi4zXzENCmRyd2ViX3Bvc3RmaXgtNC4yOS4xMGENCmRyd2ViLTQuMjkuMg0K ZHJ3ZWJfc2VuZG1haWwtNC4yOS4xMGENCmVkb25rZXktZ3VpLWd0ay0wLjUu MA0KZW5jYS0wLjEwLjcNCmVwaWM0LTEuMC4xXzINCmV2b2x1dGlvbi0xLjIu Ml8xDQpleGltLTMuMzZfMQ0KZXhpbS00LjEyXzUNCmV4aW0tbGRhcC00LjEy XzUNCmV4aW0tbGRhcDItNC4xMl81DQpleGltLW15c3FsLTQuMTJfNQ0KZXhp bS1wb3N0Z3Jlc3FsLTQuMTJfNQ0KZmFtLTIuNi45XzINCmZhc3RkZXAtMC4x NQ0KZmVoLTEuMi40XzENCmZlcml0ZS0wLjk5LjYNCmZpbGV1dGlscy00LjFf MQ0KZmluZm8tMC4xDQpmaXJlYmlyZC0xLjAuMg0KZmlyZWJpcmQtMS4wLnIy DQpmcm9udHBhZ2UtNS4wLjIuMjYyM18xDQpnYWxlb24tMS4yLjgNCmdhbGVv bjItMS4zLjJfMQ0KZ2RiLTUuM18yMDAzMDMxMQ0KZ2RiLTUuMi4xXzENCmdk bTItMi40LjEuMw0KZ2VjYy0yMDAyMTExOQ0KZ2VudG9vLTAuMTEuMzQNCmdr cmVsbG12b2x1bWUtMi4xLjcNCmdsdHJvbi0wLjYxDQpnbG9iYWwtNC41LjEN CmduYXQtMy4xNXANCmdub21lbGlicy0xLjQuMl8xDQpncHJvbG9nLTEuMi4x Ng0KZ3JhY3VsYS0zLjANCmdyaW5nb3R0cy0xLjIuMw0KZ3RyYW5zbGF0b3It MC40M18xDQpndmQtMS4yLjUNCmhlcmN1bGVzLTIuMTYuNQ0KaHRlLTAuNy4w DQpodWdzOTgtMjAwMjExDQppMzg2LXJ0ZW1zLWdkYi01LjJfMQ0KaTk2MC1y dGVtcy1nZGItNS4yXzENCmluc3RhbGx3YXRjaC0wLjUuNg0KaXZ0b29scy0x LjAuNg0KamEtZXBpYzQtMS4wLjFfMg0KamEtZ25vbWVsaWJzLTEuNC4yXzEN CmphLW1zZG9zZnMtMjAwMDEwMjcNCmphLXNhbWJhLTIuMi43YS5qMS4xXzEN CmtkZWJhc2UtMy4xXzENCmtkZWxpYnMtMy4xDQprZXJtaXQtOC4wLjIwNg0K a28tQml0Y2hYLTEuMGMxNl8zDQprby1tc2Rvc2ZzLTIwMDAxMDI3DQpsZW9j YWQtMC43Mw0KbGliZnB4LTEuMi4wLjRfMQ0KbGliZ25vbWV1aS0yLjIuMC4x DQpsaWJwZGVsLTAuMy40DQpsaWJyZXAtMC4xNi4xXzENCmxpbnV4LWJlb25l eC0wLjguMQ0KbGludXgtZGl2eHBsYXllci0wLjIuMA0KbGludXgtZWRvbmtl eS1ndWktZ3RrLTAuMi4wLmEuMjAwMi4wMi4yMg0KbGludXgtZ25vbWVsaWJz LTEuMi44XzINCmxpbnV4LW1vemlsbGEtMS4yDQpsaW51eC1uZXRzY2FwZS1j b21tdW5pY2F0b3ItNC44DQpsaW51eC1uZXRzY2FwZS1uYXZpZ2F0b3ItNC44 DQpsaW51eC1waG9lbml4LTAuMw0KbGludXhfYmFzZS02LjFfNA0KbGludXhf YmFzZS03LjFfMg0KbHNoLTEuNS4xDQpsdWtlbWZ0cGQtMS4xXzENCm02OGst cnRlbXMtZ2RiLTUuMl8xDQptaXBzLXJ0ZW1zLWdkYi01LjJfMQ0KbW9kX3Bo cDQtNC4zLjENCm1vc2Nvd19tbC0yLjAwXzENCm1vemlsbGEtMS4wLjJfMQ0K bW96aWxsYS0xLjIuMV8xLDINCm1vemlsbGEtMS4yLjFfMg0KbW96aWxsYS0x LjNiLDENCm1vemlsbGEtMS4zYg0KbW96aWxsYS1lbWJlZGRlZC0xLjAuMl8x DQptb3ppbGxhLWVtYmVkZGVkLTEuMi4xXzEsMg0KbW96aWxsYS1lbWJlZGRl ZC0xLjNiLDENCm1zeXNsb2ctMS4wOGZfMQ0KbmV0cmFpZGVyLTAuMC4yDQpv cGVuYWctMS4xLjFfMQ0Kb3BlbnNzaC1wb3J0YWJsZS0zLjVwMV8xDQpvcGVu c3NoLTMuNQ0KcDUtUFBlcmwtMC4yMw0KcGFyYWd1aS0xLjAuMl8yDQpwb3dl cnBjLXJ0ZW1zLWdkYi01LjJfMQ0KcHNpbS1mcmVlYnNkLTUuMi4xDQpwdHlw ZXMtMS43LjQNCnB1cmUtZnRwZC0xLjAuMTQNCnFpdi0xLjgNCnJlYWRsaW5r LTIwMDEwNjE2DQpyZWVkLTUuNA0Kcm94LTEuMy42XzENCnJveC1zZXNzaW9u LTAuMS4xOF8xDQpycGwtMS40LjANCnJwbS0zLjAuNl82DQpzYW1iYS0yLjIu OA0Kc2FtYmEtMy4wYTIwDQpzY3JvbGxrZWVwZXItMC4zLjExXzgsMQ0Kc2gt cnRlbXMtZ2RiLTUuMl8xDQpzaGFyaXR5LWxpZ2h0LTEuMl8xDQpzaWFnLTMu NC4xMA0Kc2tpcHN0b25lLTAuOC4zDQpzcGFyYy1ydGVtcy1nZGItNS4yXzEN CnNxdWVhay0yLjcNCnNxdWVhay0zLjINCnN3YXJtLTIuMS4xDQp0Y2wtOC4y LjNfMg0KdGNsLTguMy41DQp0Y2wtOC40LjEsMQ0KdGNsLXRocmVhZC04LjEu YjENCnRlVGVYLTIuMC4yXzENCndpbmUtMjAwMy4wMi4xOQ0Kd21sLTIuMC44 DQp3b3JrZXItMi43LjANCnhidWJibGUtMC4yDQp4ZXJjZXMtYzItMi4xLjBf MQ0KeGVyY2VzX2MtMS43LjANCnhudmlldy0xLjUwDQp4c2NyZWVuc2F2ZXIt Z25vbWUtNC4wOA0KeHNjcmVlbnNhdmVyLTQuMDgNCnh3b3JsZC0yLjANCnll bmNvZGUtMC40Nl8xDQp6aC1jbGVfYmFzZS0wLjlwMQ0KemgtdGNsLTguMy4w DQp6aC10dy1CaXRjaFgtMS4wYzE5XzMNCnpoLXZlLTEuMA0KemgteGVtYWNz LTIwLjRfMQ0KDQpJVi4gIFdvcmthcm91bmQNCg0KVGhlcmUgaXMgbm8gZ2Vu ZXJhbGx5IGFwcGxpY2FibGUgd29ya2Fyb3VuZC4NCg0KT3BlblNTSCdzIHNm dHAtc2VydmVyKDgpIG1heSBiZSBkaXNhYmxlZCBieSBlZGl0aW5nDQovZXRj L3NzaC9zc2hkX2NvbmZpZyBhbmQgY29tbWVudGluZyBvdXQgdGhlIGZvbGxv d2luZyBsaW5lIGJ5DQppbnNlcnRpbmcgYSBgIycgYXMgdGhlIGZpcnN0IGNo YXJhY3RlcjoNCg0KICBTdWJzeXN0ZW0gICAgICAgc2Z0cCAgICAvdXNyL2xp YmV4ZWMvc2Z0cC1zZXJ2ZXINCg0KbHVrZW1mdHBkKDgpIG1heSBiZSByZXBs YWNlZCBieSB0aGUgZGVmYXVsdCBmdHBkKDgpLg0KDQpWLiAgIFNvbHV0aW9u DQoNCjEpIFVwZ3JhZGUgeW91ciB2dWxuZXJhYmxlIHN5c3RlbSB0byA0Ljgt U1RBQkxFDQpvciB0byBhbnkgb2YgdGhlIFJFTEVOR181XzEgKDUuMS1SRUxF QVNFKSwgUkVMRU5HXzRfOA0KKDQuOC1SRUxFQVNFLXAxKSwgb3IgUkVMRU5H XzRfNyAoNC43LVJFTEVBU0UtcDExKSBzZWN1cml0eSBicmFuY2hlcw0KZGF0 ZWQgYWZ0ZXIgdGhlIHJlc3BlY3RpdmUgY29ycmVjdGlvbiBkYXRlcy4NCg0K MikgVG8gcGF0Y2ggeW91ciBwcmVzZW50IHN5c3RlbToNCg0KYSkgRG93bmxv YWQgdGhlIHJlbGV2YW50IHBhdGNoIGZyb20gdGhlIGxvY2F0aW9uIGJlbG93 LCBhbmQgdmVyaWZ5IHRoZQ0KZGV0YWNoZWQgUEdQIHNpZ25hdHVyZSB1c2lu ZyB5b3VyIFBHUCB1dGlsaXR5LiAgVGhlIGZvbGxvd2luZyBwYXRjaA0KaGFz IGJlZW4gdGVzdGVkIHRvIGFwcGx5IHRvIGFsbCBGcmVlQlNEIDQueCByZWxl YXNlcyBhbmQgdG8gRnJlZUJTRA0KNS4wLVJFTEVBU0UuDQoNCiMgZmV0Y2gg ZnRwOi8vZnRwLkZyZWVCU0Qub3JnL3B1Yi9GcmVlQlNEL0NFUlQvcGF0Y2hl cy9TQS0wMzowOC9yZWFscGF0aC5wYXRjaA0KIyBmZXRjaCBmdHA6Ly9mdHAu RnJlZUJTRC5vcmcvcHViL0ZyZWVCU0QvQ0VSVC9wYXRjaGVzL1NBLTAzOjA4 L3JlYWxwYXRoLnBhdGNoLmFzYw0KDQpiKSBBcHBseSB0aGUgcGF0Y2guDQoN CiMgY2QgL3Vzci9zcmMNCiMgcGF0Y2ggPCAvcGF0aC90by9wYXRjaA0KDQpj KSBSZWNvbXBpbGUgeW91ciBvcGVyYXRpbmcgc3lzdGVtIGFzIGRlc2NyaWJl ZCBpbg0KPFVSTDpodHRwOi8vd3d3LmZyZWVic2Qub3JnL2RvYy9oYW5kYm9v ay9tYWtld29ybGQuaHRtbD4uDQoNCk5PVEUgV0VMTDogIEFueSBzdGF0aWNh bGx5IGxpbmtlZCBhcHBsaWNhdGlvbnMgdGhhdCBhcmUgbm90IHBhcnQgb2YN CnRoZSBiYXNlIHN5c3RlbSAoaS5lLiBmcm9tIHRoZSBQb3J0cyBDb2xsZWN0 aW9uIG9yIG90aGVyIDNyZC1wYXJ0eQ0Kc291cmNlcykgbXVzdCBiZSByZWNv bXBpbGVkLg0KDQpBbGwgYWZmZWN0ZWQgYXBwbGljYXRpb25zIG11c3QgYmUg cmVzdGFydGVkIGZvciB0aGVtIHRvIHVzZSB0aGUNCmNvcnJlY3RlZCBsaWJy YXJ5LiAgVGhvdWdoIG5vdCByZXF1aXJlZCwgcmVib290aW5nIG1heSBiZSB0 aGUgZWFzaWVzdA0Kd2F5IHRvIGFjY29tcGxpc2ggdGhpcy4NCg0KVkkuICBD b3JyZWN0aW9uIGRldGFpbHMNCg0KVGhlIGZvbGxvd2luZyBsaXN0IGNvbnRh aW5zIHRoZSByZXZpc2lvbiBudW1iZXJzIG9mIGVhY2ggZmlsZSB0aGF0IHdh cw0KY29ycmVjdGVkIGluIEZyZWVCU0QuDQoNCkJyYW5jaCAgICAgICAgICAg ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg ICAgUmV2aXNpb24NCiAgUGF0aA0KLSAtLS0tLS0tLS0tLS0tLS0tLS0tLS0t LS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0t LS0tLS0tDQpSRUxFTkdfMw0KICBzcmMvbGliL2xpYmMvc3RkbGliL3JlYWxw YXRoLmMgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgMS42LjIu MQ0KUkVMRU5HXzRfMw0KICBzcmMvVVBEQVRJTkcgICAgICAgICAgICAgICAg ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAxLjczLjIuMjguMi4zMg0K ICBzcmMvbGliL2xpYmMvc3RkbGliL3JlYWxwYXRoLmMgICAgICAgICAgICAg ICAgICAgICAgICAgICAgICAgICAgMS45LjQuMQ0KICBzcmMvc3lzL2NvbmYv bmV3dmVycy5zaCAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAx LjQ0LjIuMTQuMi4yMg0KUkVMRU5HXzRfNA0KICBzcmMvVVBEQVRJTkcgICAg ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAxLjcz LjIuNDMuMi40NQ0KICBzcmMvbGliL2xpYmMvc3RkbGliL3JlYWxwYXRoLmMg ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgMS45LjYuMQ0KICBz cmMvc3lzL2NvbmYvbmV3dmVycy5zaCAgICAgICAgICAgICAgICAgICAgICAg ICAgICAgICAgICAxLjQ0LjIuMTcuMi4zNg0KUkVMRU5HXzRfNQ0KICBzcmMv VVBEQVRJTkcgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg ICAgICAgICAxLjczLjIuNTAuMi40NA0KICBzcmMvbGliL2xpYmMvc3RkbGli L3JlYWxwYXRoLmMgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg MS45LjguMQ0KICBzcmMvc3lzL2NvbmYvbmV3dmVycy5zaCAgICAgICAgICAg ICAgICAgICAgICAgICAgICAgICAgICAxLjQ0LjIuMjAuMi4yOA0KUkVMRU5H XzRfNg0KICBzcmMvVVBEQVRJTkcgICAgICAgICAgICAgICAgICAgICAgICAg ICAgICAgICAgICAgICAgICAgICAxLjczLjIuNjguMi40Mg0KICBzcmMvbGli L2xpYmMvc3RkbGliL3JlYWxwYXRoLmMgICAgICAgICAgICAgICAgICAgICAg ICAgICAgICAgICAxLjkuMTAuMQ0KICBzcmMvc3lzL2NvbmYvbmV3dmVycy5z aCAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAxLjQ0LjIuMjMu Mi4zMQ0KUkVMRU5HXzRfNw0KICBzcmMvVVBEQVRJTkcgICAgICAgICAgICAg ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAxLjczLjIuNzQuMi4x NA0KICBzcmMvbGliL2xpYmMvc3RkbGliL3JlYWxwYXRoLmMgICAgICAgICAg ICAgICAgICAgICAgICAgICAgICAgICAxLjkuMTIuMQ0KICBzcmMvc3lzL2Nv bmYvbmV3dmVycy5zaCAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg ICAxLjQ0LjIuMjYuMi4xMw0KUkVMRU5HXzRfOA0KICBzcmMvVVBEQVRJTkcg ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg MS43My4yLjgwLjIuMw0KICBzcmMvbGliL2xpYmMvc3RkbGliL3JlYWxwYXRo LmMgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAxLjkuMTQuMQ0K ICBzcmMvc3lzL2NvbmYvbmV3dmVycy5zaCAgICAgICAgICAgICAgICAgICAg ICAgICAgICAgICAgICAgMS40NC4yLjI5LjIuMg0KUkVMRU5HXzVfMA0KICBz cmMvVVBEQVRJTkcgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg ICAgICAgICAgICAgICAgMS4yMjkuMi4xNA0KICBzcmMvbGliL2xpYmMvc3Rk bGliL3JlYWxwYXRoLmMgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg ICAxLjExLjIuMQ0KICBzcmMvc3lzL2NvbmYvbmV3dmVycy5zaCAgICAgICAg ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAxLjQ4LjIuOQ0KLSAt LS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0t LS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tDQoNClZJSS4gIFJlZmVyZW5j ZXMNCg0KPFVSTDpodHRwOi8vaXNlYy5wbC92dWxuZXJhYmlsaXRpZXMvaXNl Yy0wMDExLXd1LWZ0cGQudHh0Pg0KPFVSTDpodHRwOi8vd3d3LmtiLmNlcnQu b3JnL3Z1bHMvaWQvNzQzMDkyPg0KLS0tLS1CRUdJTiBQR1AgU0lHTkFUVVJF LS0tLS0NClZlcnNpb246IEdudVBHIHYxLjIuMiAoRnJlZUJTRCkNCg0KaUQ4 REJRRS9MYUZ2RmRhSUJNcHMzN0lSQW9PNkFKNHpUdXRrZHA2OWZla1pHUjFB Y1pUcjQvSGRWZ0NlSzZ2Mw0KdTlCL2RvWFQ4bnMrdGtYVENiN0RYN009DQo9 b1MvRg0KLS0tLS1FTkQgUEdQIFNJR05BVFVSRS0tLS0tDQpfX19fX19fX19f X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fXw0KZnJlZWJz ZC1zZWN1cml0eUBmcmVlYnNkLm9yZyBtYWlsaW5nIGxpc3QNCmh0dHA6Ly9s aXN0cy5mcmVlYnNkLm9yZy9tYWlsbWFuL2xpc3RpbmZvL2ZyZWVic2Qtc2Vj dXJpdHkNClRvIHVuc3Vic2NyaWJlLCBzZW5kIGFueSBtYWlsIHRvICJmcmVl YnNkLXNlY3VyaXR5LXVuc3Vic2NyaWJlQGZyZWVic2Qub3JnIg0K ---825423385-869861078-1060018423=:14851 Content-Type: TEXT/PLAIN; charset=US-ASCII; name="NetBSD-SA2003-011.txt.asc" Content-Transfer-Encoding: BASE64 Content-ID: <Pine.LNX.4.55.0308041133431.14851@mail.securityfocus.com> Content-Description: Content-Disposition: attachment; filename="NetBSD-SA2003-011.txt.asc" LS0tLS1CRUdJTiBQR1AgU0lHTkVEIE1FU1NBR0UtLS0tLQ0KDQoNCgkJIE5l dEJTRCBTZWN1cml0eSBBZHZpc29yeSAyMDAzLTAxMQ0KCQkgPT09PT09PT09 PT09PT09PT09PT09PT09PT09PT09PT09DQoNClRvcGljOgkJb2ZmLWJ5LW9u ZSBlcnJvciBpbiByZWFscGF0aCgzKQ0KDQpWZXJzaW9uOglOZXRCU0QtY3Vy cmVudDoJc291cmNlIHByaW9yIHRvIEF1Z3VzdCA0LCAyMDAzDQoJCU5ldEJT RCAxLjYuMToJYWZmZWN0ZWQNCgkJTmV0QlNEIDEuNjoJYWZmZWN0ZWQNCgkJ TmV0QlNELTEuNS4zOglhZmZlY3RlZA0KCQlOZXRCU0QtMS41LjI6CWFmZmVj dGVkDQoJCU5ldEJTRC0xLjUuMToJYWZmZWN0ZWQNCgkJTmV0QlNELTEuNToJ YWZmZWN0ZWQNCg0KU2V2ZXJpdHk6CVBvc3NpYmxlIHJlbW90ZSBidWZmZXIg b3ZlcnJ1bi9yb290IGNvbXByb21pc2UNCg0KRml4ZWQ6CQlOZXRCU0QtY3Vy cmVudDoJCUF1Z3VzdCA0LCAyMDAzDQoJCU5ldEJTRC0xLjYgYnJhbmNoOglB dWd1c3QgNSwgMjAwMyAoMS42LjIgd2lsbCBpbmNsdWRlIHRoZSBmaXgpDQoJ CU5ldEJTRC0xLjUgYnJhbmNoOglBd2FpdGluZyBwdWxsdXBzDQoNCg0KQWJz dHJhY3QNCj09PT09PT09DQoNCkluIHRoZSBsaWJyYXJ5IGZ1bmN0aW9uIHJl YWxwYXRoKDMpLCB0aGVyZSB3YXMgYSBzdHJpbmcgbWFuaXB1bGF0aW9uDQpt aXN0YWtlIHdoaWNoIGNvdWxkIGxlYWQgdG8gMS1ieXRlIGJ1ZmZlciBvdmVy cnVuLiAgcmVhbHBhdGgoMykgaXMNCmJlaW5nIHVzZWQgYnkgaW1wb3J0YW50 IG5ldHdvcmsgZGFlbW9ucyBzdWNoIGFzIGZ0cGQoOCksDQp0aGVyZWZvcmUg dGhlIHZ1bG5lcmFiaWxpdHkgY291bGQgYmUgcmVtb3RlbHkgZXhwbG9pdGFi bGUuDQoNCk5vdGU6IFRoZSBzYW1lIGVycm9yIHJlbWFpbmVkIGluIGEgZGVy aXZlZCBmdW5jdGlvbiBpbiB0aGUgZGlzdHJpYnV0aW9uDQpvZiB0aGUgd3Ut ZnRwZCBzZXJ2ZXIgKE5vdCBwYXJ0IG9mIE5ldEJTRCdzIGJhc2Ugc3lzdGVt KS4gVGhpcw0KaW5mb3JtYXRpb24gaGFzIGJlZW4gYXZhaWxhYmxlIHRvIHRo ZSBnZW5lcmFsIHB1YmxpYyBmb3IgYSBtYXR0ZXIgb2YNCmRheXMgbm93LiBF eHBsb2l0cyBoYXZlIGJlZW4gcmVsZWFzZWQgYWdhaW5zdCB3dS1mdHBkLiBU aGV5IGFyZSBwcm9iYWJseQ0KYmVpbmcgd3JpdHRlbiBhZ2FpbnN0IG90aGVy IGFmZmVjdGVkIHNlcnZpY2VzIGFzIHdlbGwuIElmIHlvdSBvZmZlciBhbnkN Cm9mIHRoZSBhZmZlY3RlZCBzZXJ2aWNlcywgeW91IGFyZSBhZHZpc2VkIHRv IHBhdGNoIHlvdXIgc3lzdGVtDQppbW1lZGlhdGVseS4NCg0KDQpUZWNobmlj YWwgRGV0YWlscw0KPT09PT09PT09PT09PT09PT0NCg0KaHR0cDovL3d3dy5r Yi5jZXJ0Lm9yZy92dWxzL2lkLzc0MzA5Mg0KDQpCaW5hcmllcyBpbiB0aGUg TmV0QlNEIGJhc2Ugc3lzdGVtIHdoaWNoIHVzZSByZWFscGF0aCgzKSBpbmNs dWRlOg0KDQovYmluL3N5c3RyYWNlDQovdXNyL2xpYmV4ZWMvZnRwZCAoKikN Ci9zYmluL21vdW50DQovc2Jpbi91bW91bnQNCi91c3Ivc2Jpbi9tb3VudGQg KCopDQovdXNyL2Jpbi9zc2gNCi91c3Ivc2Jpbi9zc2hkICgqKQ0KL3Vzci9s aWJleGVjL3NmdHAtc2VydmVyICgqKQ0KL3Vzci9zYmluL2Jvb3RwZCAoKikN Cg0KQmluYXJpZXMgbWFya2VkICgqKSBsaXN0ZW4gb24gbmV0d29yayBpbnRl cmZhY2VzLCBhbmQgY291bGQgYmUgcmVtb3RlbHkNCmV4cGxvaXRhYmxlLg0K DQoNClNvbHV0aW9ucyBhbmQgV29ya2Fyb3VuZHMNCj09PT09PT09PT09PT09 PT09PT09PT09PT0NCg0KVG8gZml4IHRoaXMgdnVsbmVyYWJpbGl0eSB5b3Ug d2lsbCBuZWVkIHRvIHVwZ3JhZGUgeW91ciBsaWJjLg0KDQpUaGUgZm9sbG93 aW5nIGluc3RydWN0aW9ucyBkZXNjcmliZSBob3cgdG8gdXBncmFkZSB5b3Vy IGxpYmMNCmJpbmFyaWVzIGJ5IHVwZGF0aW5nIHlvdXIgc291cmNlIHRyZWUg YW5kIHJlYnVpbGRpbmcgYW5kDQppbnN0YWxsaW5nIGEgbmV3IHZlcnNpb24g b2YgbGliYy4NCg0KTm90ZSB0aGF0IGFsbCBzdGF0aWNhbGx5LWxpbmtlZCBi aW5hcmllcywgc3VjaCBhcyB0aGUgZm9sbG93aW5nLCBtdXN0IGJlDQpyZWJ1 aWx0Og0KLSAtIGJpbmFyaWVzIHVuZGVyIC9zYmluIGFuZCAvYmluIGZvciAx LjUgYW5kIDEuNi1iYXNlZCBzeXN0ZW1zDQotIC0gYmluYXJpZXMgdW5kZXIg L3Jlc2N1ZSBmb3IgTmV0QlNELWN1cnJlbnQgc3lzdGVtcw0KLSAtIHN0YXRp Y2FsbHktbGlua2VkIGJpbmFyaWVzIGJ1aWx0IGJ5IHBrZ3NyYw0KDQpBbHNv LCBydW5uaW5nIGluc3RhbmNlcyBvZiBkYWVtb25zIG11c3QgYmUgcmVzdGFy dGVkLCBpZiB5b3UgZG8gbm90IHBsYW4NCnRvIHJlYm9vdCB0aGUgbWFjaGlu ZSBhZnRlciB0aGUgdXBkYXRlIG9mIGxpYmMuDQoNCg0KKiBOZXRCU0QtY3Vy cmVudDoNCg0KCVN5c3RlbXMgcnVubmluZyBOZXRCU0QtY3VycmVudCBkYXRl ZCBmcm9tIGJlZm9yZSAyMDAzLTA4LTAzDQoJc2hvdWxkIGJlIHVwZ3JhZGVk IHRvIE5ldEJTRC1jdXJyZW50IGRhdGVkIDIwMDMtMDgtMDQgb3IgbGF0ZXIu DQoNCglUaGUgZm9sbG93aW5nIGRpcmVjdG9yaWVzIG5lZWQgdG8gYmUgdXBk YXRlZCBmcm9tIHRoZQ0KCW5ldGJzZC1jdXJyZW50IENWUyBicmFuY2ggKGFr YSBIRUFEKToNCgkJbGliL2xpYmMNCg0KCVRvIHVwZGF0ZSBmcm9tIENWUywg cmUtYnVpbGQsIGFuZCByZS1pbnN0YWxsIGxpYmMgYW5kIHJlc2N1ZToNCgkJ IyBjZCBzcmMNCgkJIyBjdnMgdXBkYXRlIC1kIC1QIGxpYi9saWJjDQoNCgkJ IyBjZCBsaWIvbGliYw0KCQkjIG1ha2UgVVNFVE9PTFM9bm8gY2xlYW5kaXIg ZGVwZW5kYWxsDQoJCSMgbWFrZSBVU0VUT09MUz1ubyBpbnN0YWxsDQoNCgkJ IyBjZCAuLi8uLi9yZXNjdWUNCgkJIyBtYWtlIFVTRVRPT0xTPW5vIGNsZWFu ZGlyIGRlcGVuZGFsbA0KCQkjIG1ha2UgVVNFVE9PTFM9bm8gaW5zdGFsbA0K DQoJCSh0aGVuLCByZWJvb3QsIG9yIHJlc3RhcnQgYWZmZWN0ZWQgZGFlbW9u cykNCg0KKiBOZXRCU0QgMS42LCAxLjYuMToNCg0KCVRoZSBiaW5hcnkgZGlz dHJpYnV0aW9ucyBvZiBOZXRCU0QgMS42IGFuZCAxLjYuMSBhcmUgdnVsbmVy YWJsZS4NCg0KCVN5c3RlbXMgcnVubmluZyBOZXRCU0QgMS42IHNvdXJjZXMg ZGF0ZWQgZnJvbSBiZWZvcmUNCgkyMDAzLTA4LTA0IHNob3VsZCBiZSB1cGdy YWRlZCBmcm9tIE5ldEJTRCAxLjYgc291cmNlcyBkYXRlZA0KCTIwMDMtMDgt MDUgb3IgbGF0ZXIuDQoNCglOZXRCU0QgMS42LjIgd2lsbCBpbmNsdWRlIHRo ZSBmaXguDQoNCglUaGUgZm9sbG93aW5nIGRpcmVjdG9yaWVzIG5lZWQgdG8g YmUgdXBkYXRlZCBmcm9tIHRoZQ0KCW5ldGJzZC0xLTYgQ1ZTIGJyYW5jaDoN CgkJbGliL2xpYmMNCg0KCVRvIHVwZGF0ZSBmcm9tIENWUywgcmUtYnVpbGQs IGFuZCByZS1pbnN0YWxsIGxpYmMgYW5kIHN0YXRpYw0KCWJpbmFyaWVzOg0K DQoJCSMgY2Qgc3JjDQoJCSMgY3ZzIHVwZGF0ZSAtZCAtUCAtciBuZXRic2Qt MS02IGxpYi9saWJjDQoNCgkJIyBjZCBsaWIvbGliYw0KCQkjIG1ha2UgVVNF VE9PTFM9bm8gY2xlYW5kaXIgZGVwZW5kYWxsDQoJCSMgbWFrZSBVU0VUT09M Uz1ubyBpbnN0YWxsDQoNCgkJIyBjZCAuLi8uLi9zYmluDQoJCSMgbWFrZSBV U0VUT09MUz1ubyBjbGVhbmRpciBkZXBlbmRhbGwNCgkJIyBtYWtlIFVTRVRP T0xTPW5vIGluc3RhbGwNCg0KCQkjIGNkIC4uL2Jpbg0KCQkjIG1ha2UgVVNF VE9PTFM9bm8gY2xlYW5kaXIgZGVwZW5kYWxsDQoJCSMgbWFrZSBVU0VUT09M Uz1ubyBpbnN0YWxsDQoNCgkJKHRoZW4sIHJlYm9vdCwgb3IgcmVzdGFydCBh ZmZlY3RlZCBkYWVtb25zKQ0KDQogICAgICAgIEFsdGVybmF0aXZlbHksIGFw cGx5IHRoZSBmb2xsb3dpbmcgcGF0Y2ggKHdpdGggcG90ZW50aWFsIG9mZnNl dA0KICAgICAgICBkaWZmZXJlbmNlcyk6DQogICAgICAgICAgICAgICAgZnRw Oi8vZnRwLm5ldGJzZC5vcmcvcHViL05ldEJTRC9zZWN1cml0eS9wYXRjaGVz L1NBMjAwMy0wMTEtcmVhbHBhdGgucGF0Y2gNCg0KICAgICAgICBUbyBwYXRj aCwgcmUtYnVpbGQgYW5kIHJlLWluc3RhbGwgbGliYywgYW5kIHN0YXRpYyBi aW5hcmllczoNCg0KICAgICAgICAgICAgICAgICMgY2Qgc3JjDQogICAgICAg ICAgICAgICAgIyBwYXRjaCA8IC9wYXRoL3RvL1NBMjAwMy0wMTEtcmVhbHBh dGgucGF0Y2gNCg0KCQkjIGNkIGxpYi9saWJjDQoJCSMgbWFrZSBVU0VUT09M Uz1ubyBjbGVhbmRpciBkZXBlbmRhbGwNCgkJIyBtYWtlIFVTRVRPT0xTPW5v IGluc3RhbGwNCg0KCQkjIGNkIC4uLy4uL3NiaW4NCgkJIyBtYWtlIFVTRVRP T0xTPW5vIGNsZWFuZGlyIGRlcGVuZGFsbA0KCQkjIG1ha2UgVVNFVE9PTFM9 bm8gaW5zdGFsbA0KDQoJCSMgY2QgLi4vYmluDQoJCSMgbWFrZSBVU0VUT09M Uz1ubyBjbGVhbmRpciBkZXBlbmRhbGwNCgkJIyBtYWtlIFVTRVRPT0xTPW5v IGluc3RhbGwNCg0KCQkodGhlbiwgcmVib290LCBvciByZXN0YXJ0IGFmZmVj dGVkIGRhZW1vbnMpDQoNCiogTmV0QlNEIDEuNSwgMS41LjEsIDEuNS4yLCAx LjUuMzoNCg0KCVRoZSBiaW5hcnkgZGlzdHJpYnV0aW9ucyBvZiBOZXRCU0Qg MS41LCAxLjUuMSwgMS41LjIsIGFuZCAxLjUuMw0KCWFyZSB2dWxuZXJhYmxl Lg0KDQoJQ2hhbmdlcyBoYXZlIG5vdCB5ZXQgYmVlbiBwdWxsZWQgdXAgdG8g dGhlIDEuNSBzb3VyY2UgYnJhbmNoLg0KDQoJQXBwbHkgdGhlIGZvbGxvd2lu ZyBwYXRjaCAod2l0aCBwb3RlbnRpYWwgb2Zmc2V0IGRpZmZlcmVuY2VzKToN CgkJZnRwOi8vZnRwLm5ldGJzZC5vcmcvcHViL05ldEJTRC9zZWN1cml0eS9w YXRjaGVzL1NBMjAwMy0wMTEtcmVhbHBhdGgucGF0Y2gNCg0KICAgICAgICBU byBwYXRjaCwgcmUtYnVpbGQgYW5kIHJlLWluc3RhbGwgbGliYywgYW5kIHN0 YXRpYyBiaW5hcmllczoNCg0KICAgICAgICAgICAgICAgICMgY2Qgc3JjDQog ICAgICAgICAgICAgICAgIyBwYXRjaCA8IC9wYXRoL3RvL1NBMjAwMy0wMTEt cmVhbHBhdGgucGF0Y2gNCg0KCQkjIGNkIGxpYi9saWJjDQoJCSMgbWFrZSBV U0VUT09MUz1ubyBjbGVhbmRpciBkZXBlbmRhbGwNCgkJIyBtYWtlIFVTRVRP T0xTPW5vIGluc3RhbGwNCg0KCQkjIGNkIC4uLy4uL3NiaW4NCgkJIyBtYWtl IFVTRVRPT0xTPW5vIGNsZWFuZGlyIGRlcGVuZGFsbA0KCQkjIG1ha2UgVVNF VE9PTFM9bm8gaW5zdGFsbA0KDQoJCSMgY2QgLi4vYmluDQoJCSMgbWFrZSBV U0VUT09MUz1ubyBjbGVhbmRpciBkZXBlbmRhbGwNCgkJIyBtYWtlIFVTRVRP T0xTPW5vIGluc3RhbGwNCg0KCQkodGhlbiwgcmVib290LCBvciByZXN0YXJ0 IGFmZmVjdGVkIGRhZW1vbnMpDQoNCg0KVGhhbmtzIFRvDQo9PT09PT09PT0N Cg0KQ0VSVA0KDQoNClJldmlzaW9uIEhpc3RvcnkNCj09PT09PT09PT09PT09 PT0NCg0KCTIwMDMtMDgtMDQJSW5pdGlhbCByZWxlYXNlDQoNCg0KTW9yZSBJ bmZvcm1hdGlvbg0KPT09PT09PT09PT09PT09PQ0KDQpBZHZpc29yaWVzIG1h eSBiZSB1cGRhdGVkIGFzIG5ldyBpbmZvcm1hdGlvbiBiZWNvbWVzIGF2YWls YWJsZS4NClRoZSBtb3N0IHJlY2VudCB2ZXJzaW9uIG9mIHRoaXMgYWR2aXNv cnkgKFBHUCBzaWduZWQpIGNhbiBiZSBmb3VuZCBhdCANCiAgZnRwOi8vZnRw Lk5ldEJTRC5vcmcvcHViL05ldEJTRC9zZWN1cml0eS9hZHZpc29yaWVzL05l dEJTRC1TQTIwMDMtMDExLnR4dC5hc2MNCg0KSW5mb3JtYXRpb24gYWJvdXQg TmV0QlNEIGFuZCBOZXRCU0Qgc2VjdXJpdHkgY2FuIGJlIGZvdW5kIGF0DQpo dHRwOi8vd3d3Lk5ldEJTRC5vcmcvIGFuZCBodHRwOi8vd3d3Lk5ldEJTRC5v cmcvU2VjdXJpdHkvLg0KDQoNCkNvcHlyaWdodCAyMDAzLCBUaGUgTmV0QlNE IEZvdW5kYXRpb24sIEluYy4gIEFsbCBSaWdodHMgUmVzZXJ2ZWQuDQpSZWRp c3RyaWJ1dGlvbiBwZXJtaXR0ZWQgb25seSBpbiBmdWxsLCB1bm1vZGlmaWVk IGZvcm0uDQoNCiROZXRCU0Q6IE5ldEJTRC1TQTIwMDMtMDExLnR4dCx2IDEu NyAyMDAzLzA4LzA0IDE2OjAyOjQ3IGRhdmlkIEV4cCAkDQoNCi0tLS0tQkVH SU4gUEdQIFNJR05BVFVSRS0tLS0tDQpWZXJzaW9uOiBHbnVQRyB2MS4wLjYg KE5ldEJTRCkNCkNvbW1lbnQ6IEZvciBpbmZvIHNlZSBodHRwOi8vd3d3Lmdu dXBnLm9yZw0KDQppUUNWQXdVQlB5NkVjRDVSdTIvNE4ySUZBUUdKZmdQOUhY Zi9tZmFHbXA5eTIyUGxmQStteGxUaVRmYi85TjhIDQpvdnJLTktpRVR6RlRT cjFOaS9sNHBxTnJrWURScXlQMUo0Vm5TLzZ3djFld0RZbUl6WFcxYzk4Z003 K203OTJsDQpyZ1pTa2FEV3hMeVBSVWhROE4zQkxKS01Idk1SZE5XUHVZd3lM NzZRTVZWVkZtVW84dlNsY0g4UFJOSnJqRDhLDQpGSWhJNk5RMy8rUT0NCj1k by9LDQotLS0tLUVORCBQR1AgU0lHTkFUVVJFLS0tLS0NCg== ---825423385-869861078-1060018423=:14851--